Showing posts with label Akira. Show all posts
Showing posts with label Akira. Show all posts

Tuesday, May 21, 2024

Norway Recommends Replacing SSL VPN to Prevent Breaches


 A nice cybersecurity step from Norwegian National Cyber Security Centre (NCSC).

The Norwegian National Cyber Security Centre (NCSC) recommends replacing SSLVPN/WebVPN solutions with alternatives due to the repeated exploitation of related vulnerabilities in edge network devices to breach corporate networks.


NCSC's official recommendation for users of Secure Socket Layer Virtual Private Network (SSL VPN/WebVPN) products is to switch to Internet Protocol Security (IPsec) with Internet Key Exchange (IKEv2).


IKEv1 has some vulnerabilities for some product families i.e. "IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products (CVE-2016-6415)" (CVSS 3.0 score is 7.5)


https://bit.ly/4dGmfVI


"The Norwegian National Cyber Security Centre (NCSC) recommends replacing SSLVPN/WebVPN solutions with alternatives due to the repeated exploitation of related vulnerabilities in edge network devices to breach corporate networks."


"While the cybersecurity organization admits IPsec with IKEv2 isn't free of flaws, it believes switching to it would significantly reduce the attack surface for secure remote access incidents due to having reduced tolerance for configuration errors compared to SSLVPN."


"Unlike IPsec, which is an open standard that most companies follow, SSLVPN does not have a standard, causing network device manufacturers to create their own implementation of the protocol."


"As an example, Fortinet revealed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws to breach organizations, including a Dutch military network."


"In 2023, the Akira and LockBit ransomware operations exploited an SSL VPN zero-day in Cisco ASA routers to breach corporate networks, steal data, and encrypt devices.

Earlier that year a Fortigate SSL VPN vulnerability was exploited as a zero-day against government, manufacturing, and critical infrastructure."

Tuesday, March 19, 2024

Stanford University Was Victim of a Ransomware Attack

 

Being the 3rd best university in the world doesn't make you invincible to hackers. Stanford University, which is 3rd in the world university rankings in 2023, was victim of a ransomware attack, the university announced. The data breach first occurred on May 12, 2023 and could only be detected until September 27, 2023. (After 139 days)


It is not fully clear what information was compromised but Akira, the ransomware attacker group, claimed that they have stolen 430GB worth of data, including personal information and confidential documents from Stanford University.


It seems that only a few organizations will be an exception of being ransomware victims in the future.


Be aware that cyber security threats are real and they will have a cost for you if you will be hit by them. Take necessary countermeasures against cyber threats. Most of the people are not aware of this fact but yep, they are for REAL!


https://bit.ly/48YocJK


"...toward the end of October 2023 after Akira posted Stanford to its shame site..."


"...the data breach occurred on May 12 2023 but was only discovered on September 27 of last year..."


"Akira's post dedicated to Stanford on its leak site claims it stole 430 GB worth of data, including personal information and confidential documents."


"Akira has been in operation since March 2023 and according to previous negotiations with anonymized victims that have since been published online, the group's ransom demands were varied, from multiple millions of dollars to low six-figure sums."